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IN THE CLAIMS 

Please amend the claims as follows: 

Claim 1 (Currently Amended): A method for authorizing an electronic data transfer for 
healthcare transactions comprising: 

receiving an authentication request containing a digital certificate firom a requesting 
device via a communication link; 

determining whether the digital certificate is valid; 

creating an authentication response denying the authentication request when the digital 
certificate is not valid, or approving the authentication request when the digital certificate is 
valid; 

sending the authentication response to the requesting device via the communication link; 

and 

securely storing audit trail information about the electronic data transfer, the digital 
certificate and at least a portion of the authentication response in a database, wherein securely 
storing audit trail information includes ensuring the long-term data integrity and reUabilitv of the 
audit trail information such that non-repudiation of the electronic data transfer may be 
established. 

Claim 2 (Original): The method as recited in claim 1 wherein the authentication request 
and the authentication response are transmitted via encrypted messages. 

Claim 3 (Previously Presented): The method as recited in claim 1 wherein the step of 
determining whether the digital certificate is valid comprises: 

sending a validation request for the digital certificate to a validation authority; and 


DALLAS 1607149vl 


2 


Application No.: 09/837,884 Attorney Docket No. 124521-1000 

Reply to Office Action of June 17, 2005 

receiving a validation response from the validation authority indicating whether or not the 
digital certificate is valid. 

Claim 4 (Currently Amended): The method as recited in claim 1 wherein the 
authentication response includes a date/time stamp of the authentication . 

Claim 5 (Original): The method as recited in claim 1 wherein the authentication response 
includes a digital receipt. 

Claim 6 (Original): The method as recited in claim 5 wherein the digital receipt includes 
an identification of an originator of the electronic data transfer. 

Claim 7 (Original): The method as recited in claim 5 wherein the digital receipt includes 
an identification of a recipient of the electronic data transfer. 

Claim 8 (Currently Amended): The method as recited in claim 1 wherein the audit trail 
information about the electronic data transfer includes an electronic docimient. 

Claim 9 (Currently Amended): A method for authorizing an electronic data transfer for 
healthcare transactions comprising: 

receiving an authentication request containing a digital certificate and transaction 
information about the electronic data transfer from a requesting device via a communication link; 

determining whether the digital certificate is valid; 

creating an authentication response denying the authentication request when the digital 
certificate is not valid, or approving the authentication request when the digital certificate is 
valid; 

sending the authentication response to the requesting device via the commxmication link; 
creating a digital receipt for the electronic data transfer when the digital certificate is 
valid; and 
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securely storing fee audit trail information about the electronic data transfer, the digital 
certificate and at least a portion of the authentication response in a database, wherein the audit 
trail information includes the transaction information, and securely storing audit trail information 
includes ensuring the long-term data integrity and reliability of the audit trail information such 
that non-repudiation of the electronic data transfer may be established. 

Claim 10 (Currently Amended): The method as recited in claim 9 wherein the 
authentication request, the authentication response and the transaction information about the 
electronic data transfer are transmitted via encrypted messages. 

Claim 1 1 (Preyiously Presented): The method as recited in claim 9 wherein the step of 
determining whether the digital certificate is valid comprises: 

sending a validation request for the digital certificate to a validation authority; and 

receiving a validation response from the vaUdation authority indicating whether or not the 
digital certificate is valid. 

Claim 12 (Currently Amended): The method as recited in claim 9 wherein the digital 
receipt includes a date/time stamp of the authentication . 

Claim 13 (Original): The method as recited in claim 9 wherein the digital receipt 
includes an identification of an originator of the electronic data transfer. 

Claim 14 (Original): The method as recited in claim 9 wherein the digital receipt 
includes an identification of a recipient of the electronic data transfer. 

Claim 15 (Original): The method as recited in claim 9 wherein the digital receipt 
includes an action taken relating to the electtonic data transfer. 

Claim 16 (Currently Amended): The method as recited in claim 9 wherein the audit trail 
information about the electronic data transfer includes an electronic document. 
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Claim 17 (Currently Amended): A computer program embodied on a computer readable 
medium for authorizing an electronic data transfer for healthcare transactions comprising: 

a code segment for receiving an authentication request containing a digital certificate 
from a requesting device via a conmiunication link; 

a code segment for determining whether the digital certificate is valid; 

a code segment for creating an authentication response denying the authentication request 
when the digital certificate is not valid, or approving the authentication request when the digital 
certificate is valid; 

a code segment for sending the authentication response to the requesting device via the 
communication link; and 

a code segment for securely storing audit trail information about the electronic data 
transfer, the digital certificate and at least a portion of the authentication response in a database, 
wherein securely storing audit trail information includes ensuring the long-term data integrity 
and reliability of the audit trail information such that non-repudiation of the electronic data 
transfer may be established. 

Claim 18 (Original): The computer program as recited in claim 17 wherein the 
authentication request and the authentication response are transmitted via encrypted messages. 

Claim 19 (Original): The computer program as recited in claim 17 wherein the a code 
segment for determining whether the digital certificate is valid comprises: 

a code segment for sending a validation request for the digital certificate to a validation 
authority; and 

a code segment for receiving a validation response from the validation authority 
indicating whether or not the digital certificate is valid. 
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Claim 20 (Currently Amended): The computer program as recited in claim 17 wherein 
the authentication response includes a date/time stamp of the authentication . 

Claim 21 (Original): The computer program as recited in claim 17 wherein the 
authentication response includes a digital receipt. 

Claim 22 (Original): The computer program as recited in claim 21 wherein the digital 
receipt includes an identification of an originator of the electronic data transfer. 

Claim 23 (Original): The computer program as recited in claim 21 wherein the digital 
receipt includes an identification of a recipient of the electronic data transfer. 

Claim 24 (Currently Amended): The computer program as recited in claim 17 wherein 
the audit trail information about the electronic data transfer includes an electronic document. 

Claim 25 (Currently Amended): A computer program embodied on a computer readable 
medium for authorizing an electronic data transfer for healthcare transactions comprising: 

a code segment for receiving an authentication request containing a digital certificate and 
transaction information about the electronic data transfer fi-om a requesting device via a 
commimication link; 

a code segment for determining whether the digital certificate is valid; 

a code segment for creating an authentication response denying the authentication request 
when the digital certificate is not valid, or approving the authentication request when the digital 
certificate is valid; 

a code segment for sending the authentication response to the requesting device via the 
communication link; 

a code segment for creating a digital receipt for the electronic data transfer when the 
digital certificate is valid; and 
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a code segment for securely storing the audit trail information about the electronic data 
transfer, the digital certificate and at least a portion of the authentication response in a database, 
wherein the audit trail information includes the transaction information, and securely storing 
audit trail information includes ensuring the long-term data integrity and reliability of the audit 
trail information such that non-repudiation of the electronic data transfer may be established. 

Claim 26 (Currently Amended): The computer program as recited in claim 25 wherein 
the authentication request, the authentication response and the transaction information about the 
electronic data transfer are transmitted via encrypted messages. 

Claim 27 (Original): The computer program as recited in claim 25 wherein the a code 
segment for determining whether the digital certificate is valid comprises: 

a code segment for sending a validation request for the digital certificate to a validation 
authority; and 

a code segment for receiving a validation response fi-om the validation authority 
indicating whether or not the digital certificate is vaUd. 

Claim 28 (Original): The computer program as recited in claim 25 wherein the digital 
receipt includes a date/time stamp. 

Claim 29 (Original): The computer program as recited in claim 25 wherein the digital 
receipt includes an identification of an originator of the electronic data transfer. 

Claim 30 (Original): The computer program as recited in claim 25 wherein the digital 
receipt includes an identification of a recipient of the electronic data transfer. 

Claim 31 (Original): The computer program as recited in claim 25 wherein the digital 
receipt includes an action taken relating to the electronic data transfer. 
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Claim 32 (Currently Amended): The computer program as recited in claim 25 wherein 
the audit trail information about the electronic data transfer includes an electronic document. 

Claim 33 (Currently Amended): A system for authorizing an electronic data transfer for 
healthcare transactions comprising: 

a computer; 

a data storage device communicably linked to the computer; 
a requesting device communicably linked to the computer; and 

the computer receiving an authentication request containing a digital certificate from the 
requesting device, determining whether the digital certificate is valid, creating an authentication 
response denying the authentication request when the digital certificate is not valid, or approving 
the authentication request when the digital certificate is valid, sending the authentication 
response to the requesting device, and securely storing audit trail information about the 
electronic data transfer, the digital certificate and at least a portion of the authentication response 
in a database on the data storage device , wherein securelv storing audit trail information includes 
ensuring the long-term data integrity and reUabilitv of the audit trail information such that non- 
repudiation of the electronic data transfer may be established. 

Claim 34 (Original): The system as recited in claim 33 wherein the authentication 
request and the authentication response are transmitted via encrypted messages. 

Claim 35 (Previously Presented): The system as recited in claim 33 further comprising: 

a validation authority commimicably linked to the computer via a second communication 
link; and 
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the computer determining whether the digital certificate is valid by sending a validation 
request for the digital certificate to the validation authority, and receiving a validation response 
from the validation authority indicating whether or not the digital certificate is valid. 

Claim 36 (Currently Amended): The system as recited in claim 33 wherein the 
authentication response includes a date/time stamp of the authentication . 

Claim 37 (Original): The system as recited in claim 33 wherein the authentication 
response includes a digital receipt. 

Claim 38 (Original): The system as recited in claim 37 wherein the digital receipt 
includes an identification of an originator of the electronic data transfer. 

Claim 39 (Original): The system as recited in claim 37 wherein the digital receipt 
includes an identification of a recipient of the electronic data transfer. 

Claim 40 (Currently Amended): The system as recited in claim 33 wherein the audit trail 
information about the electronic data transfer includes an electronic document. 

Claim 41 (Currently Amended): A system for authorizing an electronic data transfer for 
healthcare transactions comprising: 

a computer; 

a data storage device communicably linked to the computer; 
a requesting device communicably linked to the computer; and 
the computer receiving an authentication request containing a digital certificate and 
transaction information about the electronic data transfer from the requesting device, determining 
whether the digital certificate is valid, creating an authentication response denying the 
authentication request when the digital certificate is not valid, or approving the authentication 
request and creating a digital receipt for the electronic data transfer when the digital certificate is 


DALLAS 1607149vl 


9 


Application No.: 09/837,884 Attorney Docket No. 124521-1000 

Reply to Office Action of June 17, 2005 

valid, sending the authentication response to the requesting device, and securely storing the audit 
trail information about the electronic data transfer, the digital certificate and at least a portion of 
the authentication response on the data storage device in a database, wherein the audit trail 
information includes the transaction information, and securely storing audit trail information 
includes ensuring the long-term data integrity and reliability of the audit trail information such 
that non-repudiation of the electronic data transfer may be established. 

Claim 42 (Currently Amended): The system as recited in claim 41 wherein the 
authentication request, the authentication response and the transaction information about the 
electronic data transfer are transmitted via encrypted messages. 

Claim 43 (Original): The system as recited in claim 41 further comprising: 
a validation authority communicably linked to the computer via a second communication 
link; and 

the computer determining whether the digital certificate is valid by sending a validation 
request for the digital certificate to a validation authority, and receiving a validation response 
from the validation authority indicating whether or not the digital certificate is valid. 

Claim 44 (Original): The system as recited in claim 41 wherein the digital receipt 
includes a date/time stamp. 

Claim 45 (Original): The system as recited in claim 41 wherein the digital receipt 
includes an identification of an originator of the electronic data transfer. 

Claim 46 (Original): The system as recited in claim 41 wherein the digital receipt 
includes an identification of a recipient of the electronic data transfer. 

Claim 47 (Original): The system as recited in claim 41 wherein the digital receipt 
includes an action taken relating to the electronic data transfer. 
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Claim 48 (Currently Amended): The system as recited in claim 41 wherein the audit trail 
information about the electronic data transfer includes an electronic document. 

Claim 49 (New): The method as recited in claim 1 wherein the audit trail information is 
encrypted and signed. 

Claim 50 (New): The method as recited in claim 9 wherein the audit trail information is 
encrypted and signed. 

Claim 51 (New): The computer program as recited in claim 17 wherein the audit trail 
information is encrypted and signed. 

Claim 52 (New): The computer program as recited in claim 25 wherein the audit trail 
information is encrypted and signed. 

Claim 53 (New): The system as recited in claim 33 wherein the audit trail information is 
encrypted and signed. 

Claim 54 (New): The system as recited in claim 41 wherein the audit trail information is 
encrypted and signed. 
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